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Abstract 

The study of quantum cryptography and quantum entanglement have traditionally 
been based on two- level quantum systems (qubits). In this paper, we consider a general- 
ization of Ekert's entanglement-based quantum cryptographic protocol where qubits are 
replaced by three- level systems (qutrits). In order to investigate the security against the 
optimal individual attack, we derive the information gained by a potential eavesdropper 
applying a cloning-based attack. We exhibit the explicit form of this doner, which is 
distinct from the previously known doners, and conclude that the protocol is more robust 
than the ones based on entangled qubits as well as unentangled qutrits. 



PACS numbers: 03.65.Ud, 03.67.Dd, 89.70. +c 



1 Introduction 



Quantum cryptography aims at distributing a random key in such a way that the presence 
of an eavesdropper who monitors the quantum communication is revealed via the induced 
disturbances in the transmission of the key (for a review, see e.g. P). Practically, in order to 
realize a cryptographic protocol, it is enough that the key signal is encoded into quantum states 
that belong to incompatible bases, as in the original protocol of Bennett and Brassard known as 
BB8412J. In 1991, Ekert suggested to base the security of quantum cryptography on properties 
of the maximally entangled two-qubit state or EPR state PJ. The key signals are derived from 
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measurements when they lead to perfect correlations (same base used by the two parties), and 
otherwise data for a Bell ,4] or Clauser-Horne-Shimony-Holt (CHSH) [1| inequality test are 
collected and used to reveal the presence of an eavesdropper. Recently, it was shown that the 
violation of Bell-type inequalities is more pronounced in the case of entangled qutrits (i.e., 3- 
dimensional systems) than entangled qubits [OlUllHj- Also, several qutrit-based cryptographic 
protocols were shown to be more secure than their qubit-based counterparts EH El C2j It 
appears therefore very tempting to investigate the performances of a generalization of Ekert's 
protocol relying on a pair of entangled qutrits [T3] instead of qubits. 

^From the experimental viewpoint, there are several ways of physically realizing qutrits 
using photons. The first possibility is to utilize multiport-beamsplitters, and more specifically 
those that split the incoming single light beam into three ^3]- The second one exploits the 
polarization degree of freedom. However, since this is intrinsically a two-dimensional variable, 
one needs to use two photons per qutrit fUEi]- A third possibility, which uses only one photon 
per qutrit, exploits the spatial angular momentum of photons [HI]- Finally, another realization 
of qutrits, possibly the most straightforward one, exploits time-bins ^7]. This approach has 
already been demonstrated for entangled photons up to eleven dimensions ^H] • Thus, exploring 
an entanglement-based quantum cryptographic protocol that uses qutrits instead of qubits can 
lead to new applications of quantum informational technology as it lies in the reach of the 
current state-of-the-art quantum optical techniques. 

In what follows, we shall analyze the security of this entanglement-based protocol against 
individual attacks (where the eavesdropper Eve monitors the qutrits separately or incoherently). 
To this end, we will consider a fairly general class of eavesdropping attacks that are based on 
(state-dependent) quantum cloning machines |19| HU\ l2~T] . This will yield an upper bound on 
the acceptable error rate, which is a necessary condition for security against individual attacks, 
that is, higher error rates cannot permit to establish a secret key using one-way communication. 
We will show that this maximum acceptable error rate is higher, with this qutrit protocol, than 
with Ekert's qubit protocol, and even slightly higher than with a three-dimensional extension 
of BB84. 



2 The four qutrit bases that maximize the violation of 
local realism 

In the protocol Ekert91|3], the four qubit bases chosen by Alice and Bob (the authorized 
users of the quantum cryptographic channel) are the four bases that maximize the violation 
of the CHSH inequalities [SJ. They consist of two pairs of mutually unbiased bases 1 . When 
representing these four bases on the Bloch sphere, their eight states form a perfect octagon [see 
Fig.l (right)]. Similarly, there exists a natural generalization of this set of bases in the case of 
qutrits 22,. In analogy with the CHSH qubit bases, which belong to a great circle, these four 
qutrit bases belong to a set of bases parametrized by a phase on a generalized equator, which 

1 By definition, two orthonormal bases of an N-dimensional Hilbert space are said to be mutually unbiased 
if the norm of the scalar product between any two vectors belonging each to one of the bases is equal to -r=. 
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we shall call the 0-bases from now on. The expression of the component states of any 0-basis 
in the computational basis {|0), |1), |2)} is 

V3 k=o 

= ^^(|l>+cos(^ + ^ (1) 

with Z = 0, 1, 2. Obviously, these basis vectors form an equilateral triangle on a great circle 
centered in |1). When <fi varies, these triangles turn around |1). Note that the state |1) plays a 
privileged role compared with the states |0) and |2). The invariance under a cyclic permutation 
of the basis vectors of the computational basis is indeed broken in the 0-bases because it can 
happen that k = k' mod 3 while ^ e ik '^ (k,k' = 0, 1,2) when ^ 2|i (1=0,1,2). It has 
been shown that when local observers measure the correlations exhibited by the maximally 
entangled state 

l0 3 f ) = ^(|O)®|O) + |l)®|l) + |2)®|2)) (2) 

in the four 0-bases obtained when 0j = ff • i (with % = 0,1,2,3), then the degree of non- 
classicality that characterizes the correlations is higher than the degree of non-classicality al- 
lowed by Cirelson's theorem (2H| for qubits, and also higher than for a large class of other qutrit 
bases. This can be shown by estimating the resistance of the non-classicality of correlations 
against noise admixture jE] , or by considering generalizations of Bell inequalities to a situation 
in which trichotomic observables are considered |B| instead of dichotomic ones. Note that 
the states making up the four qutrit bases which maximize the violation of local realism (we 
shall call them the optimal bases from now on) form a perfect dodecagon, which generalizes the 
octagon encountered in the qubit case. 

Finally, it is worth noting that the state that optimizes the violation of local realism when 
considering the four optimal bases is not the maximally entangled state, but the state \4> mv ) = 

7s(|0) ® |0> + T|l> ® |1) + |2> ® |2)) where 7 = and n = 2 + 7 2 |23- This state is 

not invariant under a cyclic permutation of the basis vectors of the computational basis. We 
noted already that this invariance is broken by the 0-bases. We shall not discuss here the 
implementation of this state in quantum cryptography. 



3 Three-dimensional entanglement-based (3DEB) pro- 
tocol 

Let us now assume that the source emits the maximally entangled qutrit state and that 
Alice and Bob share this entangled pair and perform measurements along one of the four 
optimal bases described above. It is easy to check that \4>^) may be rewritten as 

103 ) = -4(|o*> ® |o;> + \u) ® |i;> + 12,> ® 12;), (3) 
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where 

\Q = ^=j:e-^^\k) (1 = 0,1,2). (4) 

Therefore, when Alice performs a measurement in the <fi basis {]/</,)} and Bob in the conjugate 
basis {|^)}, their results are 100% correlated. In addition, the four optimal bases defined above 
can be shown to be 100% correlated two by two. This can be understood by noting that phase 
conjugation corresponds to a symmetry that interchanges the bases of the dodecagon. 

It is therefore natural to consider the following generalization of the Ekert91 protocol for 
qutrits, which we shall denote the 3-dimensional entangled-based (3DEB) protocol |2Hj- In this 
protocol, Alice and Bob share the entangled state \4>t) an d choose each their measurement basis 
at random among one of the four bases maximizing violation of local realism (according to the 
statistical distribution that they consider to be optimal). Because of the existence of 100% 
correlations between measurements in local bases of the same fa, a fraction of the measurement 
outcomes can be used in order to establish a deterministic cryptographic key. The rest of the 
data, for the cases when the left and right phases are different, can be used in order to detect 
the presence of an eavesdropper for example with the of Bell inequalities of Ref. |H| or with the 
computer algorithm of Ref. [Bj. Let us now study the security of this protocol against optimal 
individual attacks. 



4 Individual attacks and optimal qutrit cloning machines 

We use a general class of cloning transformations as defined in [T§1 120[ I2T]. If Alice sends the 
input state \if)) belonging to an N- dimensional space (we will consider N = 3 later on), the 
resulting joint state of the two clones (noted A and B) and of the cloning machine (noted C) is 

N-l N-l 

m,—n )b,c — b mn U m ^ n \lp) b\ )a,c, (5) 

m,n=0 m,n=0 



where 



and 



N-l 



U m , n = J2^ Khn/N) \k + m)(k\, (6) 



k=0 

N-l 



\B m , n ) = N- 1 ' 2 £ e 2 ^ kn ^\k)\k + m), (7) 

with < m, n < N — 1. U m>n is an "error" operator: it shifts the state by m units (modulo 
N) in the computational basis, and multiplies it by a phase so as to shift its Fourier transform 
by n units (modulo N). The equation ((7|) defines the N 2 generalized Bell states for a pair of 
N-dimensional systems. 

Tracing over systems B and C (or A and C) yields the final states of clone A (or clone B): 
if the input state is the clones A and B are in a mixture of the states \tp m ,n) — U m , n \i>) 
with respective weights p mj „ and q m , n - 

N-l N-l 

PA= Pm,n\i>m,n)(ll>m,nl PB = Y Qm,n\^m,n) (4>m,n\ (8) 

m,n=0 m,n=0 
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In addition, the weight functions of the two clones {p m ,n and q m ,n) are related by 

Pm,n |^m,n| > Qm,n |^m,n| j (9) 

where a mn and 6 m>n are two (complex) amplitude functions that are dual under a Fourier 
transform [2711 12T] : 

i N-l 

bm,n = jr E e 27ri Ta xr (10) 

Let us now analyze the possibility of using such a cloning procedure in the eavesdropping 
attack on the two entangled qutrit protocol. Therefore we put N = 3. Assume that Eve clones 
the state of the qutrit that is sent to Bob (represented as the ket \ip) in Eq. |3j), and resends the 
imperfect clone (labeled by A) to Bob while she conserves the other one (labeled by B). Then, 
in analogy with JT] , Eve will measure her clone in the same basis as Bob (the basis) and her 
ancilla (labeled by C) in the conjugate basis (the 0* basis). For deriving Eve's information, we 
need first to rewrite the cloning transformation in these bases. By straightforward computations 
we get, when is equal to zero, that: 



\B m , n ) = 3- 1 / 2 Y,e im ^ {l - n)+ *%W-n);) = e™^ n ^\B_ n ^ m; ) , (11) 

1=0 

where, by definition, 

IAn*»j> = a-wj:^*n\k+)\(k + m)$, (12) 



k=0 

and 

U m , n ^e^T^p + ri)^^! = e- im ^ n+ VU n ^, (13) 

k=0 

where the tilde subscript refers to the new (0 and 0*) bases. After substitution in Eq. we 
get: 

2 2 
|^) -> J2 a m,n U m ^) A \B 

m,-n)B,C— J]] a m,n Um^^n^llp) A\B mtj>tn<t) 

)b,c, (14) 

m,n=0 m,n=0 



where the new amplitudes are defined 



rn.n ■ 



We are interested in a cloning machine that has the same effect when expressed in the four 
optimal bases, i.e. when 0j = || • i(i = 0,1,2,3). This imposes strong constraints on the 
amplitudes a m ^ n characterizing the doner, which must be of the form 

(15) 




It is possible to check that, in analogy with the qubit case j2El; such a doner is phase-covariant, 
which means that it acts identically on each state of the 0-bases. In particular, the identity 
()14j) can be shown to hold for all values of 0. The reason for this property is that, roughly 
speaking, if the doner remains invariant when expressed in several bases, then it means that 
certain combinations of Bell states possess several Schmidt bi-orthogonal decompositions. It 
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is well-known that when at least two such decompositions exist for a bipartite pure state, 
then there exist infinitely many. This explains why requiring the same cloning fidelity in two 
optimal bases (0$ = ^j, <pj = ^ with i,j = 0, 1, 2, 3 and i j) implies phase-covariance (i.e., 
cj) arbitrary). A proof of this property is out of the scope of the present paper. 

Let us now evaluate the fidelity of this phase- covariant doner for qutrits, along with the 
information that Bob and Eve obtain about Alice's state. The fidelity of the first clone (the 
one that is sent to Bob) when copying a state \ip) can be written, in general, as 

N-l 

F A =(1>\p A \lJ>)= J2 Kn| 2 |<V#m,n>r. (16) 
m,n=0 

Of course, the same relation holds for the second clone (the one that is kept by Eve) by 
replacing a m>n by b m>n . For the cloning machine defined by Eq.(jl5j). it is possible to compute 
the fidelities when cloning the component states of the -0-bases by a straightforward but lengthy 
computation. It can be shown that the fidelity of the first clone does not depend on 0, that is, 

F A = UPA\h) =v 2 + y 2 + z 2 (17) 

for all 0. The disturbances D A \ and D A2 of the first clone, defined respectively as (l^+sz. Vf — ) 
and (L 2vr \pa\10_2k ) yield both x 2 + y 2 + z 2 . Making use of Eq. (JTUJ), we obtain that, for the 
second clone, the states of the bases used in the cryptographic protocol are all copied with the 
same fidelity, which is maximum when y = z, and is given by 

F B = (v 2 + 2x 2 + I2y 2 + 8xy + Avy) /3. (18) 

Also, we get the same disturbance for all (minimal when y = z) given by Dbi = Db2 = 
(v 2 + 2x 2 + 3y 2 - Axy - 2vy)/3. 

We must now find what is the optimal strategy for Eve. In virtue of the phase-covariance 
and in order to simplify the notations, we shall from now on omit the labels that refer to the 
particular basis <fi in which the measurement is carried out. After substitution in Eq. (JHJ), we 

get 

2 

\lpk) -> 3~2 ~ C m.k-l \?Pk+rn)A\?Pl)B \lpl+m)c, (19) 

m,l=0 

where c mj - = ELoS/^" Now > = y + 5 n0 ((v - y)5 m0 + (x - y)(5 ml + 5 m2 )) so that 
Cmj = (3y8jo + (v- y)5 m0 + (x- y)(5 m i + 5 m2 )). Therefore, 

2 

l^fe) -> 3~H\^k) A {3y\^k)B\^k)c + {v-y)Yl Wi)b\^i)c) + 

1=0 

2 

|^fc+i)A(3?/|^fc)B|^fe+i)c7 + (x-y)J2 \^i)b\^i+i)c) + 

1=0 

\i>k-i)A(3yM B \^h-i)c + (x-y)J2 \^i)b\^i-i)c)}- (20) 

1=0 

After Alice's (or Bob's) measurement basis is disclosed, Eve's optimal strategy can be shown 
[TT] to be the following: first she measures both her copy B and the cloning machine C in 
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the same basis as Bob, the difference (modulo 3) of the outcomes simply giving Bob's error m. 
Conditionally on Eve's measured value of m (i.e., conditionally on Bob's error), the information 
Eve has on the state \ip) can be expressed as 



I(A:E\m = 0) = log(3) - H 

I(A:E\m^0) = log(3) - H 
where Fa = v 2 + 2y 2 since we have y 



(y + 2y) 2 {v-yf (v-yY 

3Fa 3Fa 3Fa 
2(x + 2y) 2 2{x-yf 2(x ■ 



yf 



3(1 -F A )' 3(1 -F A y 3(1 -F A )_ 
z. On average, we get for Eve's information 
Iae = F A I(A:E\m = 0) + (1 - F A ) I{A:E\m ^ 0). 
Of course, Bob's information is given by 

I -F A 1-F a 



Iab = log(3) - H 



(21) 



(22) 



(23) 



11 2 ' 2 

We now use a theorem due to Csiszar and Korner |2Zj which provides a lower bound on the secret 
key rate, that is, the rate R at which Alice and Bob can generate secret key bits via privacy 
amplification: if Alice, Bob and Eve share many independent realizations of a probability 
distribution p(a,b,e), then there exists a protocol that generates a number of key bits per 
realization satisfying 

R > m&x(I A B ~ Iae, Iab ~ I be) (24) 
In our case, Iae = I be since Eve knows exactly Bob's error m. It is therefore sufficient that 
Iab > Iae in order to establish a secret key with a non-zero rate. If we restrict ourselves to 
one-way communication on the classical channel, this actually is also a necessary condition. 
Consequently, the quantum cryptographic protocol above ceases to generate secret key bits 
precisely at the point where Eve's information matches Bob's information. 

We thus need to estimate the maximal fidelity Fa (or minimal error rate) for which a 
cloning machine exists such that Iae = Iab- This constrained optimization problem can be 
solved numerically, giving 

F A = 0.7753 (25) 

corresponding to the solution (v,x,y) = (0.8320,0.1711,0.2038). Since x ^ y, this optimal 
doner is therefore distinct from the universal qutrit doner (which clones all states with the 
same fidelity). Actually, it is slightly better than the (asymmetric) universal qutrit doner, 
which gives a fidelity F A = 0.7733 at the crossing point of Bob's and Eve's information curves 
|llj . This means that the quantum cryptographic protocol where the four mutually unbiased 
qutrit bases are used (see |9J) is slightly better than the 3DEB protocol as it admits a 0.2% 
higher error rate (1 - F A = 22.67% instead of 22.47%). 

The doner that we have derived here is an asymmetric version of the so-called two-phase- 
covariant qutrit doner that is described in [2H1 12H| [this symmetric two-phase-covariant qutrit 
doner has a fidelity (5 + VYI)/12 w 0, 760]. It copies all states of the form 3~ 1/2 (|0) + e iQ |l) + 
e 4/3 |2)) with a fidelity 0.7753 (> 0.7733) for all a and j3, while the states of the computational 
basis {|0), |1), |2)} are cloned with a lower fidelity 0.7507 (< 0.7733). Actually, its relation 
with the symmetric two-phase-covariant doner is of the same kind as the relation between the 
asymmetric universal qutrit doner (of fidelity 0.7733) and the symmetric universal qutrit doner 
(of fidelity |). 
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5 Conclusions 



The Ekert91 protocol and its qutrit extension, the 3DEB protocol which is analyzed in the 
present paper, involve encryption bases for which the violation of local realism is maximal. If 
Alice and Bob measure their member of a maximally-entangled qutrit pair in two "conjugate" 
bases, this gives rise to perfect correlations. After measurement is performed on each member 
of a sequence of maximally-entangled qutrit pairs, Alice and Bob can reveal on a public channel 
what were their respective choices of basis and identify which trit was correctly distributed, 
from which they will make the key. They can use the rest of the data in order to check that it 
does not admit a local realistic simulation. For instance they can check that their correlations 
violate some generalized Bell or CHSH inequalities. As the resistance of such a violation against 
noise is maximal when the maximally-entangled qutrit pair is measured in the optimal qutrit 
bases discussed here (and is higher than all what can be achieved with qubits), the 3DEB 
protocol is optimal from the point of view of the survival of non-classical correlations in a noisy 
environment. 

Indeed, our results imply that the 3DEB protocol is more robust against optimal incoherent 
attacks than the Ekert91 qubit protocol. This is because the optimal qubit phase-covariant 
cloning machine (which clones the optimal qubit bases involved in CHSH with the same fidelity) 
gives a somewhat higher fidelity F A = | + 4g ~ 0.8536 023 H3 ED] than Eq. In other 

words, the acceptable error rate, i. e. the error rate 1 — Fa above which the security against 
incoherent attacks is not ensured, is 22.47% for the 3DEB protocol, while it is only 14.64% for 
Ekert91. 

Recently, it has been shown that the violation of a Bell inequality extended to qutrits is 
possible, as long as the "visibility" of the two-qutrit interference exceeds V t hr = 6 ^ — 0.6962 
0|H]. The visibility mentioned above is directly related the threshold fraction of unbiased noise, 
(1 — Vthr), which has to be admixed to the maximally entangled state in order to erase the non- 
classical character of the correlations, and therefore is a measure of robustness of such a non- 
classicality jB]. This means that the non-existence of a local realistic model of the correlations 
is guaranteed if the fidelity Fa that characterizes the communication channel between Alice 
and Bob, (detectors included, so 1-Fa is the effective error rate in the transmission) is larger 
than | x 0.6962 + § » 0.7974 (instead of \ + ^ ~ 0.8536 in the case of qubits [23 13 HI) On 
the other hand, we have shown here that the 3DEB protocol is secure against a cloning-based 
individual attack, if Fa > 0.7753. Consequently, when a violation of a qutrit Bell inequality 
IB] occurs, the security of the 3DEB protocol against individual attacks is automatically 
guaranteed. Therefore, the violation of Bell inequalities is a sufficient condition for security, as 
it implies that Bob's fidelity is higher than the security threshold. Remarkably, for qubits, the 
corresponding sufficient condition (Fa > 0.8536) is also necessary [I] (this is apparently the 
case for qubits only). 

In addition, the violation of Bell inequalities guarantees that the 3DEB protocol is secure 
against so-called Trojan horse attacks during which the eavesdropper would control the whole 
transmission line and replace the signal by a fake, predetermined local-variable dependent, 
signal that mimics the quantum correlations. Such an attack can be thwarted when the signal 
is encrypted in the the optimal bases provided that the noise level is low enough (including 
now also the inefficiency of the detectors) so that no such local realistic simulation of the 
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signal does exist, and provided that Alice and Bob perform their respective choices of bases 
independently and quickly enough jM] so that their measurements are independent spatially- 
separated events. Note that all the protocols in which mutually unbiased bases are involved 
but with no entanglement (such as BB84[2], the 6-state qubit protocol jH2l E0|, or the 12-state 
qutrit protocol |9j) admit a local realistic model, so that they are not secure against Trojan 
horse attacks. 

Finally, it is interesting to compare the performances of the 3DEB protocol to those of the 
3-dimensional extension of BB84. The doner that must be used in the latter case, where two 
mutually unbiased qutrit bases are used, has a fidelity of 0.7887 jTT], thus a bit higher than the 
fidelity of the doner analyzed here, see Eq. (|25|) . Therefore, the 3DEB protocol also gives a 
slightly higher acceptable error rate than the 3-dimensional extension of BB84 (22.47% instead 
of 21.13%). This, together with the robustness with respect to Trojan horse attacks, clearly 
establishes the advantage of entanglement-based protocols with respect to BB84-like protocols. 

In summary, we have derived a qutrit cloning machine that clones equally well the four 
optimal qutrit bases (those which maximize the violation of local realism), so it gives the 
optimal individual attack in the 3DEB protocol introduced here. The acceptable error rate 
of the 3DEB protocol turns out to be 22.47%, which is higher than that of Ekert91 qubit 
protocol (as well as that of the 3-dimensional extension of BB84). Our analysis thus confirms a 
seemingly general property that qutrit schemes for quantum key distribution are more robust 
against noise than the corresponding qubit schemes. 

Note: After completion of this work, an independent paper by D. Kaszlikowski et al. has 
appeared[33j, which shows that, if Eve acts on one member of a maximally entangled qutrit pair, 
then her information attains Alice and Bob's mutual information at a visibility of 0.6629. In our 
notation, this means that the fidelity at the information crossing point is fx 0.6629+ 1 ~ 0.7753, 
which exactly coincides with our Eq. (J25|) . Nevertheless the two approaches are different in the 
following sense: in our approach, we assume that Eve clones the state of the qutrit that is 
sent to Bob according to Eq. (jSJ) and then we impose that the cloning fidelity is identical for 
all the states of the bases in order to fix the parameters a m , n . Instead, in [33], a general 
transformation is postulated from the beginning, and extra-constraints are imposed. We have 
also checked that our optimal cloning machine satisfies these constraints, so the two approcahes 
are compatible. Our approach being constructive, we obtain the explicit form of the doner, 
which is not the case in the approach of [33] ■ Moreover, although the optimal cloning machines 
coincide in both approaches, it can be shown that our approach allows us to build new and 
more general solutions that satisfies the constraints considered in 33 . 
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